Internetoptimizer trojan removal
My PC Hell Forum
November 21, 2008, 03:19:17 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Moving to New Location Soon! Watch out for notification. 14th Dec 2007.
 
   Home   Help Search Calendar Login Register  
Pages: [1]
  Print  
Author Topic: Internetoptimizer trojan removal  (Read 3907 times)
fleamailman
Rising Star
***
Posts: 344



View Profile
« on: January 05, 2006, 02:01:47 PM »

Ok, not my comp but even though I have removed this form the add/remove programes, it still puts up its add while my friend is surfing, I am looking for exact removal program. Any help welcome.
Logged

The goblin took a hike, fleamailman's account has been taken over by a different serious me then.
Essexboy
Administrator
*****
Posts: 899



View Profile WWW
« Reply #1 on: January 05, 2006, 02:12:15 PM »

Manual removal instructions here halfway down

Edit helps if I put the link in http://www.spyany.com/program/article_spy_rm_Internet_Optimizer.html
Logged

VISTA
XPsp2
Avast (of course)



http://spaces.msn.com/members/essexboymkn/

 If ignorance is bliss  why aren't more people happy?
Essexboy
Administrator
*****
Posts: 899



View Profile WWW
« Reply #2 on: January 05, 2006, 02:26:52 PM »

This might help
Quote
Description

Internet Optimizer is an error page hijacker.
Variants

InternetOptimizer/Iopti: unknown-server errors, page-missing errors, server errors and even password-required errors are redirected to Internet Optimizer’s controlling server at www.internet-optimizer.com.

InternetOptimizer/Nem: as Iopti, but searches are hijacked to yoogee.com (a search site run by the makers of InternetOptimizer).

InternetOptimizer/Wsem: a larger version of the software, whose purpose is unclear.

InternetOptimizer/Active: a reduced version that doesn’t do error page hijacking, used purely for the updater function.

InternetOptimizer/Crmrest: an ActiveX downloader control for InternetOptimizer. This poses as a comedy or porn video from the site movies-etc.com, and when allowed to install may forward a mail to all contacts in your Outlook address book, promoting movies-etc in your name.
Also known as

DyFuCA.
Distribution

May be installed by MoneyTree/DyFuCA, Roimoi, or the Crmrest downloader variant.
What it does
Advertising

Yes. The ‘DyFuCA Active Alert’ component can open pop-up ‘alerts’ when directed by its controlling server.
Privacy violation

Suspected. The EULA at Internet Optimizer’s web site states the software may send all your browsing information back to its controllers. At the time of writing, however, this has not been seen to happen with the current version of the software.
Security issues

Yes. Can download and execute arbitrary unsigned code from its controlling server, as an update feature.
Stability problems

Unknown; some unclear user reports of it causing crashes.
Removal

Check the Control Panel’s Add/Remove Programs feature for ‘Active Alert’ and ‘Internet Optimizer’. In older versions these may work if used together. Newer versions present only ‘Internet Optimizer’, which on its own has no effect.

After removal, ensure that infection vector - MoneyTree/DyFuCA, Roimoi or CrmRest is no longer loaded.
Manual removal

For the Crmrest installer variant, open the Downloaded Program Files folder (inside the Windows folder) and remove the ‘Media Manager’ entry.

For other variants, open the Windows folder. You should be able to see a file ‘ioptiXXX.dll’ (Iopti variant), ‘nemXXX.dll’ (Nem variant) or ‘wsemXXX.dll’ (Wsem variant). The XXX differs for different versions; common versions are ‘iopti130.dll’, ‘nem207.dll’ and ‘wsem210.dll’.

Open the registry (click ‘Start’, choose ‘Run’ and enter ‘regedit’) and find the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run. Delete the entries ‘DyFuCA’ and ‘DyFuCA Active Alerts’.

Now open a DOS command prompt window (from Start->Programs->Accessories), and enter the following commands (for the Iopti variant):

    cd "%WinDir%\System"
    regsvr32 /u ..\iopti130.dll

Or, for the Nem variant:

    cd "%WinDir%\System"
    regsvr32 /u ..\nem207.dll

Or, for the Wsem variant:

    cd "%WinDir%\System"
    regsvr32 /u ..\wsem210.dll

Restart the computer and you should be able to delete the DLL from the Windows folder, and the ‘DyFuCA’, ‘Internet Optimizer’ or ‘STWSI’ folder you may have inside Program Files. You can also delete the subkey ‘FCI’ in HKEY_LOCAL_MACHINE\Software and HKEY_CURRENT_USER\Software to clean up if you like.
Logged

VISTA
XPsp2
Avast (of course)



http://spaces.msn.com/members/essexboymkn/

 If ignorance is bliss  why aren't more people happy?
fleamailman
Rising Star
***
Posts: 344



View Profile
« Reply #3 on: January 05, 2006, 04:52:15 PM »

Thank you for the link, is there any one simple program that I can use to delete it, trouble is that I haven't found one yet and maually I always fear going into the regedit when it is not my machine. I am a big sissy I know but a patch, fix or scan would help.
Logged

The goblin took a hike, fleamailman's account has been taken over by a different serious me then.
Squeezebox
Administrator
******
Posts: 2756



View Profile
« Reply #4 on: January 05, 2006, 05:06:52 PM »

Can't find a removal tool for this one. However, there's only a couple of registry deletions to make according to the removal instructions.

Be bold - go for it.

Dave
Logged

fleamailman
Rising Star
***
Posts: 344



View Profile
« Reply #5 on: January 05, 2006, 07:42:39 PM »

I will ask her, thanks anyway.
Logged

The goblin took a hike, fleamailman's account has been taken over by a different serious me then.
fleamailman
Rising Star
***
Posts: 344



View Profile
« Reply #6 on: January 06, 2006, 08:49:35 AM »

She said no, also the comp is in french, regedit looks different, also I am a sissy but next time I will promise  
Logged

The goblin took a hike, fleamailman's account has been taken over by a different serious me then.
Strum
Royal Advisor
*****
Posts: 1791


Gabba Gabba Hey!


View Profile WWW
« Reply #7 on: January 06, 2006, 12:11:04 PM »

What about...save/format/reinstall or whatever?


Strum
Logged

  This is my shadows shadow...
Squeezebox
Administrator
******
Posts: 2756



View Profile
« Reply #8 on: January 06, 2006, 12:44:49 PM »

Quote from: Strum
What about...save/format/reinstall or whatever?


Strum


Maybe easier saying than doing eh?
Logged

Strum
Royal Advisor
*****
Posts: 1791


Gabba Gabba Hey!


View Profile WWW
« Reply #9 on: January 06, 2006, 01:27:10 PM »

Quote from: Squeezebox
Quote from: Strum
What about...save/format/reinstall or whatever?


Strum


Maybe easier saying than doing eh?

RE:...save/reformat/reinstall/load


I thought that that was Fleamails way of doing things...

Strum
Logged

  This is my shadows shadow...
fleamailman
Rising Star
***
Posts: 344



View Profile
« Reply #10 on: January 06, 2006, 06:36:26 PM »

No, she didn't want that either but that is what I would have done, She said she had a lot of things she wanted to keep plus lots of programs too. Romance is never easy it seems.
Logged

The goblin took a hike, fleamailman's account has been taken over by a different serious me then.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.2 | SMF © 2006-2007, Simple Machines LLC Valid XHTML 1.0! Valid CSS!